Analyze policy change impact

Before you begin

  • Enable the Policy Change Impact Analyzer toggle under Insights & Reports > Settings.

  • To view historical impacted connection counts, enable Security Analytics and Logging.

  • Policy Change Impact Analyzer currently supports Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense devices.

Procedure


Step 1

In the left pane, click Insights & Reports > Policy Change Impact Analyzer.

The Policy Change Impact Analyzer page displays an Impact Analysis summary, including the number of identified impacts.

The device list displays:

  • Device Name

  • Job Status

  • Analysis Result

Step 2

Select one or more devices, and then click Run Impact Analyzer.

You can select up to 10 devices for analysis. The analyzer evaluates the pending policy changes for the selected devices.

Step 3

Monitor the analysis in the device list.

Use the search field to search by device name, analysis result, or job status.

Step 4

Click a device row to open the details pane.

The pane displays the device status and may include these actions:

  • View change impact details to open the detailed analysis.

  • Re-analyze to generate an updated result.

  • Deploy to open the standard deployment workflow.

  • Workflows to review analysis execution details and errors.

Step 5

Click the device name to open the analysis report.

The analysis details page displays the overall impact assessment for the selected device.

Step 6

Review the Analysis Result, Rule Change Summary, Impacted Traffic Segments, Impacted Connections, and Inferred Impact.

Step 7

If the analysis is incomplete, failed, out of date, or indeterminate, review the policy manually before deployment and rerun the analysis as needed.

Note

Policy Change Impact Analyzer does not deploy, edit, approve, or reject policy changes. Use the standard deployment and change-control process after reviewing the analysis results.


The Policy Change Impact Analyzer displays the potential impact of pending access control policy changes, including changed rules, impacted traffic segments, historical connections, inferred impact, and rule change summaries.